7 ms·
As well they should. I sometimes hate the password managers too as a web developer. I am also a 1Password user, and I hate sites that block clipboard, block pas
by irae 5y ago
As well they should. I sometimes hate the password managers too as a web developer. I am also a 1Password user, and I hate sites that block clipboard, block pasting, block right click, basically block any kind of way I have to type even my username, not to mention annoying full size on screen keyboards that can only be used with the mouse.
I don't care about the reason they have to be so intrusive in UX, probably some malware fight and/or prevention. The fact is that if I am going to use 1Password or other password managers per site, with 25 characters long passwords with symbols and numbers, I want to be able to somehow fill that in without typing each letter. Some sites don't care about this use cases as they are trying to cover the asses of non-tech-savvy users. They must protect the password123 crowd, right? So password managers need to fight back, unfortunately.
- diegoperini 5y agoAutomatic field detection is fine and good UX for password managers. What is bad is auto-fill without user action.
- xzel 5y agoI have/wrote a one line auto hot key script for typing in strings in fields that don’t allow paste. Originally intended for a tax program that doesn’t allow pasting banking passwords. The pain of making a mistake and have to enter a 30+ character password over and over still haunts me. Also, if you have a problem contact their customer support. I had a tweet get a few hundred likes about a non pastable field for a transportation website and they actually changed it later that week!
- throwawayboise 5y agoWhat is the rationale for disabling paste on passwords, account numbers, other "sensitive" data? The absolute worst are fields where paste is disabled, and the characters are also echoed as "*" so you can't even see what you are typing. I saw this with SSNs when I submitted some tax forms on my state's website recently. The only argument I can think of for disabling paste (and I think it's pretty weak) is on a form to set a new password, where you need to input the password twice (and the form validates that they match) you might want to make the user actually type the same password twice, rather than let them copy/paste the first entry into the second field.
- kempbellt 5y agoWhen I used to have a multi-monitor dev environment, I did accidentally paste a password into Slack (left screen) and not Chrome (right screen). Immediately deleted the chat message and had to cycle the password. This is the only issue I've ever had with copy/pasting passwords, it only happened once, and the site preventing me from pasting would have done nothing to prevent it. I don't understand the rationale either. Also, double validating passwords should allow for pasting to promote the use of managers. Forcing users to type them in creates more possibility for mistakes - you can type the same wrong password twice... Muscle memory is funny that way.
- jakelazaroff 5y agoI’ve also accidentally typed a password into a chat app when I meant to type it into a browser. Just zoned out instead of looking at the password field where stars should have been showing up. Ultimately, people are just going to make mistakes!
- oneeyedpigeon 5y agoIf anything, pasting a password into a password field should be explicitly allowed, whilst pasting it anywhere else should either be forbidden or, possibly, prompt for confirmation first.
- robocat 5y agoWith unique passwords, the OS could introduce a filter so that when you paste a password into anything but a password field, it gets replaced by ******* à la hunter2 https://www.urbandictionary.com/define.php?term=hunter2 https://www.urbandictionary.com/define.php?term=hunter2
- rad_gruchalski 5y ago> you might want to make the user actually type the same password twice, rather than let them copy/paste the first entry into the second field Please no. I generate a password in bitwarden, save it, copy and paste twice. Don't do that. I really don't want to type a 24 character password with lower / upper letters and special characters. If you do that to me, I will leave your website and never come back.
- jimlikeslimes 5y agoI'm pretty sure Keepass/Keepassx etc do this
- SAI_Peregrinus 5y agoThey do. It's the "auto type" feature. Quite handy when sites disable paste. It also keeps passwords out of your clipboard history.
- 8ytecoder 5y agoNot to mention the 2-step flow that’s so predominant now.
- deleted 5y ago[deleted]
- sandgiant 5y agoNIST actually recommends allowing users to paste exactly for this reason: > Verifiers SHOULD permit claimants to use “paste” functionality when entering a memorized secret. This facilitates the use of password managers, which are widely used and in many cases increase the likelihood that users will choose stronger memorized secrets. https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html I use the "Don't Fuck With Paste" add on for Chrome/Firefox, which mostly works well.
- rav 5y agoHere's a bookmarklet version of "Don't mess with paste" for those who don't want to install the add-on: javascript:void(document.documentElement.addEventListener( 'copy',e=>e.stopPropagation(),true), document.documentElement.addEventListener( 'paste',e=>e.stopPropagation(),true))
- tankenmate 5y agoFor exactly this reason I wrote a script that reads from the clipboard cut buffer and inserts the keys one at a time into the keyboard input stream; voilà, pasting that side steps asinine browser page restrictions.